MailFixly

Home / Tools / Account recovery checker

Free tool · nothing leaves your browser

Could you actually get back in?

Most people find out whether their recovery works on the day it has already failed. Tick what you have set up and find out now, while you can still change the answer.

What do you have on the account?

Nothing you tick is transmitted. The score updates as you go.

Why two methods are often really one

The standard advice is to add more recovery options. It is not wrong, and it misses the part that decides whether you get back in: whether those options can fail together.

Three arrangements that look like redundancy and are not:

What people set upWhy it failsFix
Recovery email at the same providerOne provider outage, or one compromised password, takes bothUse a different company entirely
Backup codes screenshotted into the mailboxThey are inside the thing you are locked out ofPrint them, or use a password manager
Authenticator app and passkey on one phoneLose the phone and both go at onceKeep one channel off that device

This is why the checker scores channels rather than boxes ticked. Four methods that all route through one phone is a score of one.

What each method is actually worth

MethodStrengthThe catch
Recovery email (different provider)StrongOnly if you still control it. Old work addresses fail here
Authenticator appStrongTied to a device. Save its recovery codes separately
PasskeyStrongDevice-bound unless synced through your platform account
Backup codes stored offlineStrongWorthless if stored in the account
Phone numberModerateCarriers recycle numbers; Microsoft is phasing SMS out
Still-signed-in deviceWeakA session, not recovery. Ends without warning
Password in a managerWeakPrevents needing recovery; does nothing once you do

If the answer was bad

Fix it now rather than resolving to. The whole failure mode of account recovery is that the work is only ever urgent at the exact moment it has become impossible.

Provider-specific walkthroughs: recovering a Hotmail or Outlook account, adding non-phone recovery to a Google account, and what to use instead of a phone number if that is what you were avoiding.

Frequently Asked Questions

Does this tool see my account or my details?
No. It asks only which recovery methods you have set up, never what they are. There is no network request anywhere in the page, nothing is logged and nothing is stored. You can confirm it by opening your browser developer tools and watching the network tab while you use it.
Why does it care about independent channels rather than how many methods I have?
Because methods that depend on the same thing fail together. A recovery email at the same provider, backup codes saved into the mailbox they unlock, and an authenticator on the phone you just lost all look like redundancy and provide none. Two genuinely independent channels protect you better than four that share one.
Is a phone number enough on its own?
It is better than nothing and weaker than people assume. Numbers get recycled by carriers when a contract lapses, SMS can be intercepted, and Microsoft is actively phasing SMS out as a verification method. As the only channel it is a single point of failure.
Where should backup codes actually be stored?
Anywhere that is not the account they unlock. Printed and kept with your passport, or in a password manager you can reach from another device. Codes screenshotted into the same mailbox are inaccessible in precisely the situation they exist for.
Does a Resilient result mean I can never be locked out?
No. It means you hold more than one independent route back in, which is the part you control. Providers can still lock an account for reasons unrelated to recovery, and an automated decision can take time to reverse.

Why You Can Trust This Tool

  • Nothing is transmitted. There is no network request in this page. Check the network tab.
  • No credentials requested. It never asks what your recovery methods are, only whether you have them.
  • Independently built. Not affiliated with, endorsed by, or sponsored by Google or Microsoft.
  • Last reviewed: .